4.3

CVE-2021-22924

Exploit
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or can be, case sensitive on many systems but not all, and caneven vary depending on used file systems.The comparison also didn't include the 'issuer cert' which a transfer can setto qualify how to verify the server certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Libcurl Version >= 7.10.4 < 7.77.0
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Cloud Backup Version -
Oracle ≫ Mysql Server Version >= 5.7.0 <= 5.7.36
Oracle ≫ Mysql Server Version >= 8.0.0 <= 8.0.26
Siemens ≫ Ruggedcomrm 1224 Lte Firmware Version < 7.1
   Siemens ≫ Ruggedcomrm 1224 Lte Version -
Siemens ≫ Scalance M804pb Firmware Version < 7.1
   Siemens ≫ Scalance M804pb Version -
Siemens ≫ Scalance M812-1 Firmware Version < 7.1
   Siemens ≫ Scalance M812-1 Version -
Siemens ≫ Scalance M816-1 Firmware Version < 7.1
   Siemens ≫ Scalance M816-1 Version -
Siemens ≫ Scalance M826-2 Firmware Version < 7.1
   Siemens ≫ Scalance M826-2 Version -
Siemens ≫ Scalance M874-2 Firmware Version < 7.1
   Siemens ≫ Scalance M874-2 Version -
Siemens ≫ Scalance M874-3 Firmware Version < 7.1
   Siemens ≫ Scalance M874-3 Version -
Siemens ≫ Scalance M876-3 Firmware Version < 7.1
   Siemens ≫ Scalance M876-3 Version -
Siemens ≫ Scalance M876-4 Firmware Version < 7.1
   Siemens ≫ Scalance M876-4 Version -
Siemens ≫ Scalance Mum856-1 Firmware Version < 7.1
   Siemens ≫ Scalance Mum856-1 Version -
Siemens ≫ Scalance S615 Firmware Version < 7.1
   Siemens ≫ Scalance S615 Version -
Siemens ≫ Simatic Cp 1543-1 Firmware Version < 3.0.22
   Siemens ≫ Simatic Cp 1543-1 Version -
Siemens ≫ Simatic Cp 1545-1 Firmware Version < 1.1
   Siemens ≫ Simatic Cp 1545-1 Version -
Siemens ≫ Simatic Rtu3010c Firmware Version < 5.0.14
   Siemens ≫ Simatic Rtu3010c Version -
Siemens ≫ Simatic Rtu3030c Firmware Version < 5.0.14
   Siemens ≫ Simatic Rtu3030c Version -
Siemens ≫ Simatic Rtu3031c Firmware Version < 5.0.14
   Siemens ≫ Simatic Rtu3031c Version -
Siemens ≫ Simatic Rtu 3041c Firmware Version < 5.0.14
   Siemens ≫ Simatic Rtu 3041c Version -
Siemens ≫ Sinema Remote Connect Version < 3.1
Siemens ≫ Siplus Net Cp 1543-1 Firmware Version < 3.0.22
   Siemens ≫ Siplus Net Cp 1543-1 Version -
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version 9.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.27% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CISA-ADP 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
Patch
Third Party Advisory
https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cdev.kafka.apache.org%3E
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc%40%3Cusers.kafka.apache.org%3E
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cdev.kafka.apache.org%3E
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7%40%3Cusers.kafka.apache.org%3E
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/08/msg00017.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2022/08/msg00017.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FRUCW2UVNYUDZF72DQLFQR4PJEC6CF7V/
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5197
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-732250.pdf
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210902-0003/
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf
Third Party Advisory
https://hackerone.com/reports/1223565
Patch
Third Party Advisory
Exploit
Issue Tracking